Red Hat Security Advisory: Red Hat Single Sign-On 7.4.4 security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2020-10695 — containers/redhat-sso-7: /etc/passwd is given incorrect privileges CVE-2020-13822 — nodejs-elliptic: improper encoding checks allows a certain degree of signature malleability in ECDSA signatures CVE-2020-25638 — hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments and JPQL String literals are used CVE-2020-25649 — jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE) CVE-2020-27826 — keycloak: Account REST API can update user metadata attributes
🎯 Affected products1
- Text-Only RHSSO
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update). Workaround: Set hibernate.use_sql_comments to false, which is the default value, or use named parameters instead of literals. Please refer to details in https://docs.jboss.org/hibernate/orm/5.4/userguide/html_single/Hibernate_User_Guide.html#configurations-logging and https://docs.jboss.org/hibernate/orm/5.4/userguide/html_single/Hibernate_User_Guide.html#sql-query-parameters. Workaround: There is currently no known mitigation for this flaw.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2020:5533
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1817530
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1848647
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1881353
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1887664
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1905089
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_5533.json